SHA256
1
0
forked from pool/openCryptoki
Commit Graph

164 Commits

Author SHA256 Message Date
Dominique Leuenberger
3535ace4c8 Accepting request 761262 from security
OBS-URL: https://build.opensuse.org/request/show/761262
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=55
2020-01-07 22:52:36 +00:00
Mark Post
22f37498e5 Accepting request 761261 from home:markkp:branches:security
- Added oki-3.12-EP11-Fix-EC-uncompress-buffer-length.patch (bsc#1159114)
  The EP11 token may fail to import an ECC public key. Function
   C_CreateObject returns CKR_BUFFER_TOO_SMALL in this case.

OBS-URL: https://build.opensuse.org/request/show/761261
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=104
2020-01-06 19:39:12 +00:00
Dominique Leuenberger
5a672f85f2 Accepting request 753057 from security
- Upgraded to version 3.12.1 (bsc#1157863)
  * Fix pkcsep11_migrate tool

OBS-URL: https://build.opensuse.org/request/show/753057
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=54
2019-12-03 11:42:46 +00:00
Mark Post
1470911ed6 OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=102 2019-12-02 21:42:49 +00:00
Mark Post
c0154ab939 - Upgraded to version 3.12.0 (jsc#SLE-7647, jsc#SLE-7915, jsc#SLE-7918)
* Update token pin and data store encryption for soft,ica,cca and ep11
  * EP11: Allow importing of compressed EC public keys
  * EP11: Add support for the CMAC mechanisms
  * EP11: Add support for the IBM-SHA3 mechanisms
  * SOFT: Add AES-CMAC and 3DES-CMAC support to the soft token
  * ICA: Add AES-CMAC and 3DES-CMAC support to the ICA token
  * EP11: Add config option USE_PRANDOM
  * CCA: Use Random Number Generate Long for token_specific_rng()
  * Common rng function: Prefer /dev/prandom over /dev/urandom
  * ICA: add SHA*_RSA_PKCS_PSS mechanisms
  * Bug fixes
- Removed obsolete ocki-3.11.1-EP11-Support-tolerated-new-crypto-cards.patch

- Added ocki-3.11.1-EP11-Support-tolerated-new-crypto-cards.patch
  (bsc#1152015)
  Add support for new IBM crypto card.

OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=101
2019-12-02 21:40:41 +00:00
Dominique Leuenberger
cbd45d26e5 Accepting request 747496 from security
- Upgraded to version 3.12.0 (jsc#SLE-7647, jsc#SLE-7915, jsc#SLE-7918)
  * Update token pin and data store encryption for soft,ica,cca and ep11
  * EP11: Allow importing of compressed EC public keys
  * EP11: Add support for the CMAC mechanisms
  * EP11: Add support for the IBM-SHA3 mechanisms
  * SOFT: Add AES-CMAC and 3DES-CMAC support to the soft token
  * ICA: Add AES-CMAC and 3DES-CMAC support to the ICA token
  * EP11: Add config option USE_PRANDOM
  * CCA: Use Random Number Generate Long for token_specific_rng()
  * Common rng function: Prefer /dev/prandom over /dev/urandom
  * ICA: add SHA*_RSA_PKCS_PSS mechanisms
  * Bug fixes
- Removed obsolete ocki-3.11.1-EP11-Support-tolerated-new-crypto-cards.patch
- Added ocki-3.11.1-EP11-Support-tolerated-new-crypto-cards.patch
  (bsc#1152015)
  Add support for new IBM crypto card.

OBS-URL: https://build.opensuse.org/request/show/747496
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=53
2019-11-12 10:56:28 +00:00
Mark Post
e32a01b2c9 OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=99 2019-11-12 06:10:24 +00:00
Mark Post
c1dc5b2de9 OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=98 2019-11-12 06:09:22 +00:00
Mark Post
013583e4c0 OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=97 2019-11-12 06:08:06 +00:00
Mark Post
b8166a529f OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=96 2019-11-12 06:02:35 +00:00
Mark Post
fa64604504 OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=95 2019-11-12 06:02:02 +00:00
Mark Post
be04f8e20e - Upgraded to version 3.12.0 (jsc#SLE-7647, jsc#SLE-7915, jsc#SLE-7918)
* Update token pin and data store encryption for soft,ica,cca and ep11
  * EP11: Allow importing of compressed EC public keys
  * EP11: Add support for the CMAC mechanisms
  * EP11: Add support for the IBM-SHA3 mechanisms
  * SOFT: Add AES-CMAC and 3DES-CMAC support to the soft token
  * ICA: Add AES-CMAC and 3DES-CMAC support to the ICA token
  * EP11: Add config option USE_PRANDOM
  * CCA: Use Random Number Generate Long for token_specific_rng()
  * Common rng function: Prefer /dev/prandom over /dev/urandom
  * ICA: add SHA*_RSA_PKCS_PSS mechanisms
  * Bug fixes
- Removed obsolete ocki-3.11.1-EP11-Support-tolerated-new-crypto-cards.patch

- Added ocki-3.11.1-EP11-Support-tolerated-new-crypto-cards.patch
  (bsc#1152015)
  Add support for new IBM crypto card.

- Upgraded to version 3.11.1 (Fate#327837)
  Bug fixes.
- Dropped obsolete ocki-3.11-Fix-target_list-passing-for-EP11-session.patch

- Added ocki-3.11-Fix-target_list-passing-for-EP11-session.patch
  (bsc#1123988)

- Do not ignore errors from groupadd. If groupadd fails,
  installation ought not to proceed because files would have the
  wrong ownership.

- Don't hide error messages from the groupadd command. To eliminate

OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=94
2019-11-12 06:00:01 +00:00
Mark Post
f819296223 OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=93 2019-11-12 05:57:00 +00:00
Mark Post
125bf08e32 OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=92 2019-11-12 05:40:48 +00:00
Mark Post
d6fbf12ace Accepting request 747465 from home:markkp:branches:security
- Upgraded to version 3.12.0 (jsc#SLE-7647, jsc#SLE-7894, jsc#SLE-7915, jsc#SLE-7918)
  * Update token pin and data store encryption for soft,ica,cca and ep11
  * EP11: Allow importing of compressed EC public keys
  * EP11: Add support for the CMAC mechanisms
  * EP11: Add support for the IBM-SHA3 mechanisms
  * SOFT: Add AES-CMAC and 3DES-CMAC support to the soft token
  * ICA: Add AES-CMAC and 3DES-CMAC support to the ICA token
  * EP11: Add config option USE_PRANDOM
  * CCA: Use Random Number Generate Long for token_specific_rng()
  * Common rng function: Prefer /dev/prandom over /dev/urandom
  * ICA: add SHA*_RSA_PKCS_PSS mechanisms
  * Bug fixes
- Removed obsolete ocki-3.11.1-EP11-Support-tolerated-new-crypto-cards.patch
- Added ocki-3.11.1-EP11-Support-tolerated-new-crypto-cards.patch
  (bsc#1152015)
  Add support for new IBM crypto card.

OBS-URL: https://build.opensuse.org/request/show/747465
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=91
2019-11-12 05:07:33 +00:00
Dominique Leuenberger
9a0779e2dd Accepting request 728363 from security
OBS-URL: https://build.opensuse.org/request/show/728363
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=52
2019-09-05 10:46:48 +00:00
Mark Post
b9b0c3bdde Accepting request 728362 from home:markkp:branches:security
Upgrade to 3.11.1

OBS-URL: https://build.opensuse.org/request/show/728362
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=89
2019-09-04 22:38:50 +00:00
Dominique Leuenberger
83aa39444a Accepting request 676277 from security
OBS-URL: https://build.opensuse.org/request/show/676277
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=51
2019-02-15 09:04:16 +00:00
Mark Post
61fa2dac51 Accepting request 676276 from home:markkp:branches:security
- Added ocki-3.11-Fix-target_list-passing-for-EP11-session.patch
  (bsc#1123988)

OBS-URL: https://build.opensuse.org/request/show/676276
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=87
2019-02-15 05:33:31 +00:00
Dominique Leuenberger
273033a82d Accepting request 655691 from security
OBS-URL: https://build.opensuse.org/request/show/655691
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=50
2018-12-07 13:35:57 +00:00
4008088d68 Accepting request 652754 from home:jengelh:branches:security
- Do not ignore errors from groupadd. If groupadd fails,
  installation ought not to proceed because files would have the
  wrong ownership.

OBS-URL: https://build.opensuse.org/request/show/652754
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=85
2018-12-06 13:55:44 +00:00
Mark Post
521acbf5c9 OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=84 2018-11-30 18:20:32 +00:00
Dominique Leuenberger
3087c3c1ce Accepting request 652748 from security
OBS-URL: https://build.opensuse.org/request/show/652748
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=49
2018-11-30 15:32:50 +00:00
Mark Post
78bf8e7c8a Accepting request 652747 from home:markkp:branches:security
Misc changes

OBS-URL: https://build.opensuse.org/request/show/652747
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=82
2018-11-29 23:15:22 +00:00
Mark Post
482abee6f9 OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=81 2018-11-29 22:50:26 +00:00
Mark Post
f072b8698a - Don't hide error messages from the groupadd command. To eliminate
a potentially common one, check to see if the pkcs11 group is
  already defined before trying to add it.
- Update the summary for the -devel package.
- Changed several PreReq entries to Requires(pre) as a result of
  the output from spec-cleaner. Removed a couple of obsolete lines.

OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=80
2018-11-29 22:49:07 +00:00
Dominique Leuenberger
bc9b0c7ad7 Accepting request 649627 from security
OBS-URL: https://build.opensuse.org/request/show/649627
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=48
2018-11-20 21:42:30 +00:00
Mark Post
e7f80fc66d Accepting request 649626 from home:markkp:branches:security
- Upgraded to version 3.11.0 (Fate#325685)
  * opencryptoki 3.11.0
    EP11 enhancements
    A lot of bug fixes
- Reworked the ocki-3.1-remove-make-install-chgrp.patch to apply
  properly to 3.11, and renamed it to
  ocki-3.11-remove-make-install-chgrp.patch
- Removed obsolete patch ocki-3.5-icsf-coverity-memoryleakfix.patch
- Upgraded to version 3.10.0 (Fate#325685)
  * opencryptoki 3.10.0
    Add support to ECC on ICA token and to common code.
    Add SHA224 support to SOFT token.
    Improve pkcsslotd logging.
    Fix sha512_hmac_sign and rsa_x509_verify for ICA token.
    Fix tracing of session id.
    Fix and improve testcases.
    Fix spec file permission for log directory.
    Fix build warnings.
* opencryptoki 3.9.0
    Fix token reinitialization
    Fix conditional man pages
    EP11 enhancements
    EP11 EC Key import
    Increase RSA max key length
    Fix broken links on documentation
    Define CK_FALSE and CK_TRUE macros
    Improve build flags
- Dropped obsolete patch ocki-3.8.2-Fix-Hardware-Feature-Object-validation-and-tests.patch
- Made multiple changes to the spec file based on spec-cleaner output.
- Added an rpmlintrc file to squelch warnings about adding ghost
  entries for files under /var/log/opencryptoki/

OBS-URL: https://build.opensuse.org/request/show/649626
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=78
2018-11-16 16:33:50 +00:00
Dominique Leuenberger
aa50de6dc7 Accepting request 597603 from security
- Added ocki-3.8.2-Fix-Hardware-Feature-Object-validation-and-tests.patch
  (bsc#1086678)

OBS-URL: https://build.opensuse.org/request/show/597603
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=47
2018-04-19 13:31:21 +00:00
Mark Post
4866a500c9 Accepting request 597601 from home:markkp:branches:security
- Added ocki-3.8.2-Fix-Hardware-Feature-Object-validation-and-tests.patch
  (bsc#1086678)

OBS-URL: https://build.opensuse.org/request/show/597601
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=76
2018-04-17 23:10:57 +00:00
Dominique Leuenberger
9a4d74717d Accepting request 585158 from security
OBS-URL: https://build.opensuse.org/request/show/585158
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=46
2018-03-11 14:25:39 +00:00
Mark Post
4539918c49 Accepting request 585157 from home:markkp:branches:security
- Re-enabled ARM architectures now that gcc6 is in SLE15. (bsc#1084617)

OBS-URL: https://build.opensuse.org/request/show/585157
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=74
2018-03-09 20:17:11 +00:00
Dominique Leuenberger
cd7943207e Accepting request 546864 from security
OBS-URL: https://build.opensuse.org/request/show/546864
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=45
2017-12-03 09:12:49 +00:00
Mark Post
cfbd8bf303 Accepting request 546863 from home:markkp:branches:security
- Upgraded to version 3.8.2 (fate#323295, bsc#1066412)
  * v3.8.2
    Update man pages.
    Improve ock_tests for parallel execution.
    Fix FindObjectsInit for hidden HW-feature.
    Fix to allow vendor defined hardware features.
    Fix unresolved symbols.
    Fix tracing.
    Code/project cleanup.
  * v3.8.1
    Fix TPM data-structure reset function.
    Fix error message when dlsym fails.
    Update configure.ac
    Update travis.
  * v3.8.0
    Multi token instance feature.
    Added possibility to run opencryptoki with transactional memory or locks
      (--enable-locks on configure step).
    Updated documentation.
    Fix segfault on ec_test.
    Bunch of small fixes.

OBS-URL: https://build.opensuse.org/request/show/546863
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=72
2017-12-01 02:02:32 +00:00
Dominique Leuenberger
6165f39b1f Accepting request 500232 from security
Fix for bsc#1039510

OBS-URL: https://build.opensuse.org/request/show/500232
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=44
2017-06-01 14:34:51 +00:00
Mark Post
3d264fa667 Accepting request 500228 from home:markkp:branches:security
Fix for bsc#1039510

OBS-URL: https://build.opensuse.org/request/show/500228
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=70
2017-05-31 20:09:13 +00:00
Dominique Leuenberger
0c6c511ab1 Accepting request 494813 from security
Updated to version 3.7.0 (Fate#321451) (bsc#1036640)

OBS-URL: https://build.opensuse.org/request/show/494813
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=43
2017-05-16 12:45:19 +00:00
Mark Post
cd6812de23 - Updated to version 3.7.0 (Fate#321451) (bsc#1036640)
- Update example spec file
  - Performance improvement. Moving from mutexes to transactional memory.
  - Add ECDSA SHA2 support for EP11 and CCA.
  - Fix declaration of inline functions.
  - Fix wrong testcase and ber en/decoding for integers.
  - Check for 'flex' and 'YACC' on configure.
  - EP11 config file rework.
  - Add enable-debug on travis build.
  - Add testcase for C_GetOperationState/C_SetOperationState.
  - Upgrade License to CPL-1.0
  - Ica token: fix openssh/ibmpkcs11 engine/libica crash.
  - Fix segfault and logic in hardware feature test.
  - Fix spelling of documentation and manuals.
  - Fix the retrieval of p from a generated rsa key.
  - Coverity scan fixes - incompatible pointer type and unused variables.

OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=67
2017-05-12 09:06:41 +00:00
Dominique Leuenberger
bfbc78d27e Accepting request 491366 from security
1

OBS-URL: https://build.opensuse.org/request/show/491366
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=42
2017-04-28 07:14:00 +00:00
Mark Post
5f9d2f2ce9 Accepting request 491365 from home:markkp:branches:security
Added libica-tools to the BuildRequires due to repackaging of libica.

OBS-URL: https://build.opensuse.org/request/show/491365
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=65
2017-04-26 20:28:06 +00:00
Dominique Leuenberger
399e119092 Accepting request 481629 from security
1

OBS-URL: https://build.opensuse.org/request/show/481629
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=41
2017-03-24 01:21:54 +00:00
Mark Post
f168c8daed Accepting request 481628 from home:markkp:branches:security
Missed a second BuildRequires for libica3-devel.

OBS-URL: https://build.opensuse.org/request/show/481628
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=63
2017-03-20 21:54:09 +00:00
Mark Post
18e79c3575 Accepting request 481620 from home:markkp:branches:security
Missed a second BuildRequires for libica3-devel.

OBS-URL: https://build.opensuse.org/request/show/481620
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=62
2017-03-20 21:47:43 +00:00
Dominique Leuenberger
294be4d5ed Accepting request 480952 from security
1

OBS-URL: https://build.opensuse.org/request/show/480952
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=40
2017-03-18 19:51:04 +00:00
Mark Post
4d86d0db29 Accepting request 480951 from home:markkp:branches:security
Fix problem with building on 32bit systems and make libica-devel requirement more generic.

OBS-URL: https://build.opensuse.org/request/show/480951
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=60
2017-03-17 22:23:40 +00:00
Mark Post
9b51cd5951 Accepting request 480948 from home:markkp:branches:security
Fix problem with building on 32bit systems and make libica-devel requirement more generic.

OBS-URL: https://build.opensuse.org/request/show/480948
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=59
2017-03-17 22:13:25 +00:00
Dominique Leuenberger
3ff97425b0 Accepting request 460935 from security
1

OBS-URL: https://build.opensuse.org/request/show/460935
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=39
2017-03-03 16:44:34 +00:00
Mark Post
1e158a83bf Accepting request 460930 from home:markkp:branches:security
Upgraded to version 3.6.2 (fate#321451)

OBS-URL: https://build.opensuse.org/request/show/460930
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=57
2017-02-28 17:15:00 +00:00
Dominique Leuenberger
d71451abde Accepting request 451674 from security
Upgraded to latest version per IBM request (fate#321451)

OBS-URL: https://build.opensuse.org/request/show/451674
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openCryptoki?expand=0&rev=38
2017-01-24 09:38:17 +00:00
Mark Post
e9742235f7 - Removed reference to pkcs1_startup from pkcsslotd (bsc#1007081)
OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=55
2017-01-17 20:14:46 +00:00